Processes
Path
|
Cmdline
|
Malicious
|
|
---|---|---|---|
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.4XLRdxcWyU /tmp/tmp.rlhPtjlBJN /tmp/tmp.3Jy8t3HbEW
|
||
/usr/bin/dash
|
-
|
||
/usr/bin/rm
|
rm -f /tmp/tmp.4XLRdxcWyU /tmp/tmp.rlhPtjlBJN /tmp/tmp.3Jy8t3HbEW
|
||
/tmp/res.arm.elf
|
/tmp/res.arm.elf
|
||
/tmp/res.arm.elf
|
-
|
||
/tmp/res.arm.elf
|
-
|
||
/tmp/res.arm.elf
|
-
|
||
/usr/libexec/gnome-session-binary
|
-
|
||
/bin/sh
|
/bin/sh -e -u -c "export GIO_LAUNCHED_DESKTOP_FILE_PID=$$; exec \"$@\"" sh /usr/libexec/gsd-print-notifications
|
||
/usr/libexec/gsd-print-notifications
|
/usr/libexec/gsd-print-notifications
|
||
/usr/libexec/gsd-print-notifications
|
-
|
||
/usr/libexec/gsd-print-notifications
|
-
|
||
/usr/libexec/gsd-printer
|
/usr/libexec/gsd-printer
|
||
/usr/bin/xfce4-session
|
-
|
||
/usr/bin/rm
|
rm -f /home/saturnino/.cache/sessions/Thunar-2ec9153f1-6fa0-4067-96b1-e5fe875b1e51
|
There are 6 hidden processes, click here to show them.
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
145.138.43.7
|
unknown
|
Netherlands
|
||
56.235.255.113
|
unknown
|
United States
|
||
139.214.210.5
|
unknown
|
China
|
||
131.50.205.233
|
unknown
|
United States
|
||
243.117.124.153
|
unknown
|
Reserved
|
||
33.154.79.55
|
unknown
|
United States
|
||
191.170.192.71
|
unknown
|
Brazil
|
||
79.183.135.100
|
unknown
|
Israel
|
||
91.153.97.198
|
unknown
|
Finland
|
||
49.132.73.56
|
unknown
|
Japan
|
||
216.192.157.207
|
unknown
|
United States
|
||
103.140.126.36
|
unknown
|
China
|
||
147.254.40.109
|
unknown
|
United States
|
||
126.210.18.79
|
unknown
|
Japan
|
||
158.107.95.64
|
unknown
|
United States
|
||
219.23.126.1
|
unknown
|
Japan
|
||
116.81.214.63
|
unknown
|
Japan
|
||
35.251.200.174
|
unknown
|
United States
|
||
240.238.27.55
|
unknown
|
Reserved
|
||
176.150.184.67
|
unknown
|
France
|
||
154.128.36.239
|
unknown
|
Egypt
|
||
9.223.8.64
|
unknown
|
United States
|
||
180.160.115.249
|
unknown
|
China
|
||
51.199.42.112
|
unknown
|
United Kingdom
|
||
167.127.215.87
|
unknown
|
United States
|
||
82.244.132.198
|
unknown
|
France
|
||
220.230.195.227
|
unknown
|
Korea Republic of
|
||
48.157.193.139
|
unknown
|
United States
|
||
50.141.103.226
|
unknown
|
United States
|
||
104.100.101.227
|
unknown
|
United States
|
||
113.105.235.33
|
unknown
|
China
|
||
101.169.208.230
|
unknown
|
Australia
|
||
254.185.15.66
|
unknown
|
Reserved
|
||
23.144.124.94
|
unknown
|
Reserved
|
||
158.130.94.138
|
unknown
|
United States
|
||
103.229.252.35
|
unknown
|
Japan
|
||
32.128.22.131
|
unknown
|
United States
|
||
213.194.38.211
|
unknown
|
Spain
|
||
13.125.237.146
|
unknown
|
United States
|
||
3.232.129.130
|
unknown
|
United States
|
||
22.63.115.27
|
unknown
|
United States
|
||
66.35.125.35
|
unknown
|
United States
|
||
182.80.99.106
|
unknown
|
China
|
||
123.145.54.244
|
unknown
|
China
|
||
139.194.113.145
|
unknown
|
Indonesia
|
||
124.201.215.167
|
unknown
|
China
|
||
37.162.142.47
|
unknown
|
France
|
||
73.148.125.85
|
unknown
|
United States
|
||
19.128.124.217
|
unknown
|
United States
|
||
97.226.218.165
|
unknown
|
United States
|
||
102.70.125.70
|
unknown
|
Malawi
|
||
198.53.27.127
|
unknown
|
Canada
|
||
118.12.106.75
|
unknown
|
Japan
|
||
211.15.92.61
|
unknown
|
Japan
|
||
174.179.119.158
|
unknown
|
United States
|
||
240.221.222.14
|
unknown
|
Reserved
|
||
213.40.160.128
|
unknown
|
United Kingdom
|
||
53.152.207.130
|
unknown
|
Germany
|
||
183.50.221.195
|
unknown
|
China
|
||
6.109.109.105
|
unknown
|
United States
|
||
37.5.253.133
|
unknown
|
Germany
|
||
188.70.77.253
|
unknown
|
Kuwait
|
||
213.131.182.219
|
unknown
|
United Kingdom
|
||
40.0.146.79
|
unknown
|
United States
|
||
94.244.131.199
|
unknown
|
Ukraine
|
||
115.247.124.237
|
unknown
|
India
|
||
209.158.250.82
|
unknown
|
United States
|
||
96.240.122.32
|
unknown
|
United States
|
||
36.74.194.4
|
unknown
|
Indonesia
|
||
141.229.171.248
|
unknown
|
unknown
|
||
44.210.72.159
|
unknown
|
United States
|
||
67.149.59.186
|
unknown
|
United States
|
||
21.224.150.35
|
unknown
|
United States
|
||
17.185.134.171
|
unknown
|
United States
|
||
155.182.122.211
|
unknown
|
United States
|
||
2.215.37.99
|
unknown
|
Germany
|
||
52.158.3.52
|
unknown
|
United States
|
||
96.188.78.69
|
unknown
|
United States
|
||
72.191.193.63
|
unknown
|
United States
|
||
160.1.138.36
|
unknown
|
United States
|
||
65.40.218.31
|
unknown
|
United States
|
||
152.36.230.144
|
unknown
|
United States
|
||
70.164.99.139
|
unknown
|
United States
|
||
98.42.141.9
|
unknown
|
United States
|
||
99.136.160.189
|
unknown
|
United States
|
||
219.66.9.167
|
unknown
|
Japan
|
||
46.22.42.204
|
unknown
|
Germany
|
||
84.101.196.85
|
unknown
|
France
|
||
27.223.62.219
|
unknown
|
China
|
||
209.177.149.112
|
unknown
|
United States
|
||
255.54.130.194
|
unknown
|
Reserved
|
||
50.114.10.166
|
unknown
|
United States
|
||
54.167.122.28
|
unknown
|
United States
|
||
78.175.81.9
|
unknown
|
Turkey
|
||
52.89.193.15
|
unknown
|
United States
|
||
105.66.24.171
|
unknown
|
Morocco
|
||
195.241.86.234
|
unknown
|
Netherlands
|
||
135.96.123.148
|
unknown
|
United States
|
||
248.124.155.122
|
unknown
|
Reserved
|
||
150.29.179.136
|
unknown
|
Japan
|
There are 90 hidden IPs, click here to show them.
Memdumps
Base Address
|
Regiontype
|
Protect
|
Malicious
|
|
---|---|---|---|---|
7f98a4021000
|
page read and write
|
|||
7f98ab8f3000
|
page read and write
|
|||
7f98aa71b000
|
page read and write
|
|||
7ffccf58f000
|
page read and write
|
|||
55e740d15000
|
page read and write
|
|||
7f98ab711000
|
page read and write
|
|||
7f98abbfd000
|
page read and write
|
|||
7f98aafb5000
|
page read and write
|
|||
7f98ab5a5000
|
page read and write
|
|||
7f97a4029000
|
page read and write
|
|||
55e742d13000
|
page execute and read and write
|
|||
7f98abad4000
|
page read and write
|
|||
7ffccf595000
|
page execute read
|
|||
7f98ab582000
|
page read and write
|
|||
7f98abc21000
|
page read and write
|
|||
7f98abc66000
|
page read and write
|
|||
7f97a402a000
|
page read and write
|
|||
55e74475a000
|
page read and write
|
|||
7f97a4021000
|
page execute read
|
|||
55e740d0c000
|
page read and write
|
|||
7f98a3fff000
|
page read and write
|
|||
55e742d2a000
|
page read and write
|
|||
7f98ab317000
|
page read and write
|
|||
55e740abb000
|
page execute read
|
|||
7f98aaf23000
|
page read and write
|
There are 15 hidden memdumps, click here to show them.